EIP-2026-113498

PRE-CVE

WordPress Core 2.2 - 'wp-app.php' Arbitrary File Upload

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-113498. PoCs published by Alexander Concha.

AI-analyzed exploit summary This Perl script exploits an arbitrary file upload vulnerability in WordPress 2.2 and WordPress MU <= 1.2.2 by leveraging authenticated user privileges to upload a file via a PUT request to a vulnerable endpoint. It automates authentication, post creation, and file upload to achieve remote code execution.

Description

WordPress Core 2.2 - 'wp-app.php' Arbitrary File Upload

Exploits (1)

exploitdb WORKING POC VERIFIED
by Alexander Concha · perlwebappsphp
https://www.exploit-db.com/exploits/4113

This Perl script exploits an arbitrary file upload vulnerability in WordPress 2.2 and WordPress MU <= 1.2.2 by leveraging authenticated user privileges to upload a file via a PUT request to a vulnerable endpoint. It automates authentication, post creation, and file upload to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WordPress 2.2, WordPress MU <= 1.2.2
Auth required
Prerequisites: Valid WordPress user credentials with author/editor/administrator role · Access to the target WordPress installation
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026